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REPORT 

Copy Protection Technical Working Group 
June 21, 1996 

I. Introduction 

As a result of the increasing capability to represent and distribute all types of 
content in digital form, there is considerable interest in copyright management 
schemes capable of protecting the legitimate rights of the owners of all forms of 
content and software in the electronic environment. 

This report summarizes the main technical discussions of an ad-hoc group 
which met on four occasions between May 9 and May 30 1996 in order to 
evaluate the potential technological approaches to providing copy protection 
and rights management capabilities to linear motion picture content, as well as 
other forms of copyrighted content including sound recordings, in the PC 
environment, environments where a PC could be interposed, and the consumer 
electronics environment. 

The main purpose of these discussions was to provide a neutral technical input 
to the plenary group, without prejudice to the outcome of further discussions 
regarding associated non-technical considerations. The plenary group is 
compnsed of both policy and technical representatives of the member 
companies of the MPAA, CEMA, BSA, ITIC, RIAA and IMA. 

In view of the limited time available to the technical group, the discussions were 
primanly focused on linear motion picture content and the copy protect 
scenarios related to the introduction of the DVD in particular. Even so, the 
discussions focused on overall evaluation of the merits and drawbacks of 
general classes of potential technological approaches, without drawing any 
final conclusions about the details of actual implementations or designs. 

Although several broader issues were identified, they will require further activity 
beyond the work of this group in order to be addressed. 

II. Objectives and scope 

With the introduction of consumer digital devices capable of playing, 
transmitting and recording digital linear motion pictures, the capability for 
making and distributing high quality copies or re-transmissions of the original 
copyrighted material has increased. In the digital environment the degradations 
which are unavoidably associated with the equivalent analog processes are 
absent so this natural inhibition to copying is much reduced, even eliminated. 

The overall objective of the group was to identify and evaluate technical 
approaches which could potentially be used to protect content in analog or 
digital form, delivered by direct electronic transmission or prerecorded media.' 
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against copying in analog or digital recorders or against re-transmissions in a 
form contrary to the usage conditions intended by the owner of the copyright, or 
contrary to legitimate and reasonable consumer usage. Analog to analog copy 
scenarios were not included within the group's agenda for discussion. 

The scope of the technology evaluation included 

1) the level of effectiveness of the copy protection for motion 
picture content and other forms of content such as sound 
recordings and software 

2) whether the technology is "fail-safe", i.e. can remain effective 
in protecting the content, even in those devices that do not 
implement the scheme. 

3) the impact on the intended usage of the content (i.e. there should 
be no noticeable degradation of the original material or of 
permissible copies) 

4) the impact on cost 

5) the impact on performance 1 

6) the impact on product schedules 

7) the extensibility of the approach with respect to potential 
future upgrades, including backward compatibility 

8) the applicability to existing or legacy devices 



III. Basic properties and desirable attributes 

. The desirable attributes of the copy protection scheme for linear motion picture s&a* 
reuJj^js content include 

1) protection for digital linear motion pictures, including segments 

as small as single frames, and sound recordings including samples. 

2) a level of protection that will prevent the average consumer from 
unlawfully making and/or distributing copies or re-transmissions, 
i.e. 'keep honest people honest 1 

3) capability to deal with three primary options for usage conditions, 
as well as a method for associating those options with the content 
in a persistent way, 
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a) copying is permitted 

b) copying is not permitted 

c) one generation only of copying is permitted 

4) capability to address current and future classes of content sources 
and destinations, including 

a) digital to digital 

b) digital to analog 

c) analog to digital 

where the digital devices include dedicated, stand-alone consumer 
video recording and playback products in addition to general 
purpose digital recording and playback devices associated with 
computing systems. The analog devices include existing VHS, 8mm 
and other formats of consumer analog video recorders, as well* as 
the analog interfaces to consumer digital video recorders. The 
digital and analog interfaces to computers are also included. 

5) capability for application on an international basis 

6) capability to offer a range of copy protection and rights 
management alternatives to the content owner, having various 
levels of cost, complexity and effectiveness. 

7) capability to limit the potential exposure resulting from a breach 
in the system 

From the viewpoint of consumer electronics hardware and computer systems 
manufacturers, the desirable attributes of the copy protect implementation 
include 

1 ) acceptably low or insignificant impact on the cost, performance 
manufacturability and availability of devices 

2) compatibility with accepted standards and existing devices 

3) compatibility with existing processes and architectures 

4) upgrade capability with backward compatibility 

5) broad applicability to all forms of content or software in the 
computer environment 

6) applicability to prerecorded disc media of both the stamped and 
the directly written kind 
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7) capability to provide copy management of copyrighted material 
in both computer and consumer electronic environments 



IV. Technical evaluations 
A. General observations 

The group reached an overall consensus on two principal recommendations 
which merit further investigation and evaluation in terms of specific 
implementation proposals to determine mutually acceptable and effective cop 
protection and management schemes 

1) in the case of digital content information, the content itself 
should be protected prior to initial distribution by direct 
application of some combination of encryption and/or scrambling 
type encoding by the copyright owner. The advantage of such 
'self-protected' content is that no special digital copy 
restrictions need be applied to the content while it exists in 
encrypted and/or scrambled form. The keys necessary to decrypt 
and/or de-scramble the content for display, copying or 
re-transmission purposes are only provided to devices when the 1 
usage is consistent with the defined conditions, whether 

these devices are part of the local system or connected remotely 
through a digital transmission interface. 

2) the basic information concerning the usage conditions should be 
embedded within the active content data stream, even though for 
the purposes of some consumer electronic devices it may, in 
addition, be carried as associated data along with the content 
stream. The advantages of such 'self-describing 1 content having 
embedded control data, particularly in those environments which 
include computers, are that it 

a) ensures that the usage conditions are available 

to any transmission interface or recording device which bases 
compliant operation on detection of, and response to this 
information 

b) guarantees the transmission of the control information 
between the digital and/or analog input/output interfaces 

of computer systems. Since computer systems and processes 
preserve the active content data stream, no special actions 
would be required to assure transmission of the embedded 
control information. 
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Table 1 shows the group's evaluations of four general approaches to 
encryption based schemes. woacnes to 

Table 2 shows the group's evaluation of embedded data schemes for 
schemes US39e C ° nditi ° nS 33 C ° mpared t0 "^-embedded 

B. Specific environments considered 
1) Digital to Digital 

™ V n?^ ni Pr ° V ! de con J sumers access to high quality digital linear motion picture 
content sound record.ngs and computer software, and requires the most 
immediate solution for copy protection. Of several schemes that were 
described most favored those which included scrambling and/or encryption of 

SUrgffiS: ^ D k DR ? M medla in ° rd6r 10 COntrol "nauthS 

dSS^SS nZV aS6d on , enCrypted and/or scramb,ed conte ^ were 
Described by both IT and consumer electronics companies. Not onlv do such 

approaches provide protection to the content on the DVDROM media but ?he 

content also remains protected even in those systems which did no impfement 

copy protects, i.e. such schemes can be fail-safe. The etiectWene^STe 

schemes, as well as their impact on the schedule and cost SoSISSted 

with the mtroduction of DVD products will, of course, depend on Thfffna details 

of the chosen implementation as it is developed. 

HS-f^ ° f en °T ed < ° 0ntent al0ne does n6t P revent the making of encrypted 
digita cop.es. Therefore, for DVD-R or DVD-RAM devices in particular, 7he 
overall copy protect and rights management scheme will require a me hod to 
allow playback of a copy by a DVD player or drive only when that copy complies 
with the usage conditions set forth by the content owner. Playback contral ' 
schemes were described which were based on the method for key 
TmhSrH en \? rthr0U9h com P arison be tween special (watermark) data 
diT If ' n J 6 , 00 ^ and data Physically embedded in the original ROM 
mediT bSn^ P h l e ' th f ' , n0t PreS6nt ' ° r has a different valua the recordable 
one ^oenlr" tL rth6r b requlred 38 to how such scne mes could support 

drcumXSTtS^ f nd S6rial C ° Py mana 9 em ent, and under what P 
circumstances these features are required. 

Shtf° UP r6VieWed a PP roa ches to the secure delivery of digital content and 
hone sch n pT. mem inf0rmatl ° n baSed on di 9» al conLner technologies. 

med, a S S3 , me COntainer and carried dlrect, y °" the DVD 

7atr SrmLpVth" Th * S ° n ' y deCrypted When software on the com P"ter or 
kev ^marUZSt r L 1 ? C ° nditi ° nS have been met Alternatively, the 
lo XhT^aZ o^Z ^ aSS ' 9ned t0 3 remote tmsted a 9 ent - and released 
aaencv and thl h 0nly °" com P |et ion °* & specific transaction between the 
agency and the drive or end-user. Such approaches are capable of affording 
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high levels of effectiveness in the future when the digital content is transmits 
o the consumer by direct electronic means. In that case the key exchanae 
transacts could be a natural component of the overall transaction S 
mean time, applicability of digital container technology to the disinbu ,on of 
content on DVDROM requires further study. aistnoution of 

Representatives of the sound recording industry described copy management 
systems they recommend for sound recordings. These systems included 
copyright management using a bi-directional authorization system from source 
to end user, time windows, embedded signaling and recordable areas on 
stamped discs. 

2) Digital to Analog 

Two types of analog video outputs, in addition to optional audio outputs mav be 
present on a computer: RGB, and NTSC. Y 

(a) The RGB output is necessary for output to the computer 
display and therefore is almost always present as part of the 
computer system. The precise definition of the RGB output signal 

is dependent on both the display parameters and computer systems' 
manufacturers specifications. In general, dedicated consumer ' 
video recorders do not accept RGB inputs so that, in order to 
make an analog copy from this interface, a format converter to 
NTSC, or other consumer recordable analog video format is 
required. 

(b) The NTSC analog output is typically not present on the installed 
base of computers, however if an NTSC analog output is 
optionally present, then the output signal may be directly 
connected to a consumer video recorder. Depending on the 
overall evolution of applications for computer systems, the 
inclusion of an NTSC video output may become more prevalent in 
the future. 



The existing base of analog consumer VCRs (i.e. VHS, 8mm and Beta, for 
example) presents an immediate capability to make analog copies from DVD or 
other digital source material via the NTSC video output. These analog 
consumer VCR machines have no ability to either detect or respond directly to 
mormation regarding usage conditions, whether directly embedded or 
?* d ' n association with the content signal. As a result, copy protection in 
rn™ ? J 9 ^ VCR domain mus t take the approach of rendering the 
!LT ' ° r 3t least extrem ely unsatisfactory during playback. Such 
Thl r^rlnt ri 9 ! n M a " y be referred t0 as anal °9 Protection systems, or APS. 
The current method (developed by the Macrovision Corporation works by 
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using this kind of approach. By placing certain signal features into the vertical 
blanking interval and/or periodically modifying the color burst signal, the 
recording circuits of the VCR are disturbed in a way that results in a substandard 
recording being made to the cassette. These same features do not similarly upset 
the input circuits of television sets t so analog signals incorporating the APS 
eatures may remain viewable even when copy protected. 

If analog protection signal features are applied to the analog video signals 
encoded on the NTSC video outputs of computers or format converters attached 
to the RGB outputs of computers, they would provide the equivalent level of 
protection against copies made to consumer analog VCRs as is currently 
experienced. Similarly, the absence of analog signal protection features will 
result in an NTSC video signal output which is unprotected and may be copied 
without technical impediments by a consumer analog VCR. 

No presentations on potential approaches to providing APS on the RGB output 
were made to the group, and discussions concerning initial concepts were 
largely inconclusive in terms of identifying an effective and satisfactory 
approach. 

3) Analog to Digital 

The basis for copy protection with respect to stand-alone digital video recording 
devices consists of two main elements. 

a) The control data expressing the content owners usage conditions 
is always associated with the content data. Embedding the control 
data into the active part of the content data ensures that from the 
computer system viewpoint the data is, by default, preserved 
through all normal processes which protect the content itself. The 
group also discussed the use of embedded data in the audio signal 
accompanying the linear motion picture to carry the usage conditions 
associated with the rights management. 

b) Dedicated stand-alone digital video recording devices (such as the 
DVCR) which receive the content must detect and respond to the 
control data in a compliant fashion. Although DVCR products 
generally have implemented copy protection methods based on active 
response to control data, to date such data has not been embedded 
directly in the content. If the control data scheme is not of the 
embedded type, and if the digital output is to be communicated to 
such a dedicated stand-alone video recording device, then the 
associated control data would need to be applied at the appropriate 
digital output of the computer during the overall DVCR (or other) 
format encoding process, in a manner analogous to that described in 
section B.2) with respect to any analog protection signal features applied 
during the NTSC encoding process. 
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In order for the analog source data (or initially digital-to-analog converted 
source data) to be output as a converted-to-digital copy signal to be recorded bv 
future recordable DVD media, there will need to be consumer-level access to 
DVD encoding capability in the computer system, including the capability for 
MPEG2 compression. In this circumstance, the combined effect of 
authentication via embedded data (or watermarks) and playback control 
methods, as mentioned above in the section on digital to digital, will provide a 
capability for copy protection of the analog source material. 

No technical methods were found to prevent the copying of the (initially-analog- 
to-digital) converted video content to general purpose removable media digital 
storage devices (excluding the recordable DVD devices already discussed in 
the previous paragraph). However, the relatively low penetration of such 
devices, coupled with the relatively high cost for both media and drives 
significantly limits their utility to support copying of motion pictures in the 
consumer environment. 

C. Recommended future activity for the technical group 

The broad consideration and evaluation of the technological approaches which 
might form the basis for a mutually acceptable and reasonably effective copy 
protection scheme has now been completed by the technical group. The 
technical group recommends that the next phase consist of entering into more 
detailed and open technical discussions involving the development of specific 
proposals on the detailed specifications for copy protection. At that point, all 
parties can better evaluate the technical and economic viability of the proposed 
approaches described in this report. This work should focus at first on the near 
term issues involved in the DVD player and DVD-ROM areas, and then expand 
to cover all the relevant channels for the distribution and transmission of 
copyright content of all forms where rights management schemes are thought to 
be beneficial. 



M-5921 




I 

! 



Li 
ill 

M M M 

OfNO 



i 1 





s 



St 




Or 

s 



Q. 



9 



I 



JIJI. 

228 



>->•>- 



a> «u o 

II Z I 



2 2 >- 2 2 



* 

5 



I 



I 



to 



ft 



5 8 



CM 

8 8? 



>->->->->- 



I 



SI 

"I 

E S* 



5 

2 .£?»>- 



2 g >- 



8 8 I 



I 

u 



f 



cr 

§ 

a 



§2 

T8 



2 



>- |$ >- >- 
>- 



8 8^8 



V 4) V 

II? : 



CO 



II 



s S _ g s 




!Hsi 



Q 

S I5 



fll 
Iff 

m O 2 



.a 



M-: 



5922 



CO 
QO 

8 



5 



o 
o 



Q 

Q 



li 

I? 



1 



CO 

iS > 
ro co 
Q 

_ Ql 

"S | 
"' o 



f 



JS 

8 








N 
N 
N 

(visibility), reduced by data hi 


NoforSVS 
Yes in general 
No 


CO 

> 












Small 





||0 o 

gur 

<o - " 

s 



31 

~~ o 

i 

in 





■= o o ^ 



5 

> iSOn 
Q Q. C 0l 



Q a <r 5. o 



§ 5 




• § 2 U § 



M-5923 



Attachments 



The following are summaries which were received of some of the proposals 
which were presented to the group during the course of the series of four 
meetings. The are provided, as attachments to the main body of the report, 
in the form submitted and without editorial or other revisions by the 
co-chairs. 

Further information is available by contacting one of the co-chairs. 
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DIGITAL TO DIGITAL COPY PROTECTION 

Apple Computer 
Paul Wehrenberg 

ABSTRACT 

Data Encryption and Decryption 

St' s l n i q w a no .u f ? r , a volunta jy system of copy protection is encryption of the data to 
be protected, so that dear text does not appear on the media. In this proposal the main 
data stream is encrypted by segmenting sectors and scrambling the segments in 
sequential groups of sectors. For example, if 16 sectors (32 KB of user data) are 
segmented and the trailing segment of each sector randomly concatenated with a leadina 
1 J new 2KB blocks result out of 161 possible combinations. The information to 
correctly order these segments is contained in a 16 element (64 bit) scrambling vector 
which is itself encrypted using a key which is hidden on the media. One nibble of the 
nCf 3ES .f f-ambling vector is placed in the header of each sector, creating no additional 
overhead if the reserved area is used. During playback, the encrypted scrambling vector 

uXfV TOm the S eaders ' d < 5*B l8d using *• from »• the leTSSSreSf 
S™^? 6 oorrectly reassembled, and the data used by the destination process The 
scrambling scheme is designed to be computationally intensive to break if attacked as a iio 
saw puzzle, but easy to reorder if the key is available. 19 

Key Placement and Exchange 

S^Hi" 6 ^. 3 .,™ 3 nufacture one . k ey or group of keys is placed on the media in a location or 
sub channel that is only accessible to the drive controller. It is not in an area that is 
addressable by logical block address (LBA). This key will be the message for a public 
key/private key transaction through the open computer system. 

The drive controller is possessed of a public key and a private key, and has the 
capabi ity of receiving another entity's public key. The drive can then encrypt a message 
using its private key and the received public key. This encrypted message can be 
requested by the operating system and passed to the owner of the non drive public key. 

At startup the DVD-ROM device driver requests the Operating System to provide 
certified public keys of legitimate destination processes (HAV or SAW running in the 
y -J\ J he dri y e I for the destination process also requests the Operating System to 
82 * 6 Ce ® d pu < lic . key of the drive - Performing this function only at startup limits 
media key 9 3 Spoofer ^ P rocess t0 establish a session with the drive and obtain the 

2fJ je » s . t L nat,on P ro 5 e ss then uses its own private key and the drive's public key to 
decrypt the received message. As noted above, the message is the key(s) on the media. 

The transaction described above uses very robust encryption which may be 
computationally intensive. However the size of the message is relatively small 
and the transaction is done infrequently, in some instances only at startup. 
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Summary of a Copy Protection Scheme for DVD 
Hewlett Packard Labs, 17th June, 1996 
Josh Hogan 

This Copy Protection Scheme is based on encoding a decryption key or an 
identification number in the channel coded bit stream, in a manner that will not 
be transferred by direct copying of the files on a disc. 

The DVD encoder will include a state machine that will have the ability to select 
more than one codeword to represent at least some symbols. Such an encoder 
can correctly represent data symbol sequences with multiple bit pattern strings, 
all of which are valid. This choice of bit patterns is intended to allow the low 
frequency content of the bit stream to be minimized, but could also be used for 
encoding decryption keys or identification numbers onto the bit stream. 
Furthermore, the nature of the encoder allows a small number of codeword 
choices to have a dramatic effect on the encoded bit stream. In particular the 
statistics of the different runs of zeros in the bit stream can vary for different 
encoding of the same user data. The decryption key is derived from the bit 
stream by accumulating the run length statistics of a specified 32kbyte data 
block and then decoding these statistics according to a criteria set contained on 
the disc. 1 

When a movie disc is played or a software package is installed from a disc, the 
first step of the play or installation routine, is to instruct the player to access the 
relevant 32kbyte blocks, accumulate the run length statistics of these blocks and 
generate the decryption key from the criteria also contained on the disc. It then 
instructs the player to read and decrypt the encrypted 32kbyte data blocks (or to 
decrypt blocks, or sections of blocks, on the fly). 

If a copy of the disc is made, however, the new disc will have a bit stream with 
different run length statistics and so, will no longer contain the ability to 
generate the correct decryption key. 

A valuable aspect of this approach to "hiding" the key on the disc is that in order 
to make an unauthorized copy of the disc, both software and hardware hacking 
have to occur. Specifically the install or play software routine must be analyzed 
in order to determine which 32kbyte data blocks contain the decryption keys 
and the bit stream endocing must be analyzed in order to determine the original 
channel coding that must be recreated to yield the keys. 

This scheme for hiding the keys on the disc can be used with many different 
types of actual encryption or scrambling implementations. It forms one 
important element in an overall solution. This approach to that important 
element of any protection scheme (i.e. how to hide the key on the disc), is also 
applicable to both stamped and written discs. 



Tel 415 857 7335 FAX 415 857 7724 
E-Mail josh_hogan@hp1900.hp.com 
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Synopsis of Proposals Submitted by 
Matsushita Electric Industrial Co., Ltd. 

In the interest of furthering the technical discussions on digital to digital copy protection 
Matsushita Electnc has put forward two basic proposals: A) "Content Scrambled DVD" 
and B) "Bus Authentication and Encryption" using different encryption, authentication ' 
and placement strategies, which it feels address in a practical and timely way the ' 
diverse concerns of consumer electronics, movie, and information technology 
industries. The two approaches summarized below can be used separately or in 
combination to provide different levels of effectiveness and "fail-safe" dependent on 
different legislative regimes. In PC environments, the proposal "B)" should be used in 
combination with the proposal "A)". 

A) "Content Scrambled DVD" 

Under this proposal the DVD content would be scrambled (encrypted) prior to 
producing a master which is then used to replicate separate discs during 
manufacturing. Data can be scrambled on a sector by sector basis with certain disc 
navigation information left in the clear for better control during playback. The chosen 
scrambling method provides protection equally well for all forms of content (movie 
audio, or other ROM type data). For best security and speed descrambling would be 
done on chip before the audio 

and video decoding process. Various key management and associated authentication 
strategies are possible to implement resulting in different levels of simplicity 
effectiveness, and vulnerability. One method uses a "encrypted disckey" stored in the 
hidden lead-in area (key changed for each master), as well as separate encrypted 
keys for each title which are stored in the sector header area. An important feature of 
this approach is that a stand-alone DVD movie player can be designed which uses 
only descramblmg/decryption, and thus easily meets export regulations. 

B) "Bus Authentication and Encryption" 

In this proposal an encryption process would be included in the DVD-ROM drive 
output circuitry connected to the computer bus, and complementary decryption would 
men be performed at the decoder also attached to the bus. Keys would be transmitted 
in a secure form over the standard bus from the DVD-ROM drive to the audio and 
v.deo decoder as a result of a two stage bi-directional authentication process. For this 
purpose time varying key sharing should be used. Because this approach does not 
depend on the content of the source being encrypted, when incorporated in the 
computer bus interface it can provide security during transmissions within the 
computer for a wide variety of internal and externally attached digital media and 
electronic delivery services. 
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InterTrust™ Copy Protection and Rights 
Management for Consumer Appliances and 

Computers 



Executive Summary 

Presented By 
Electronic Publishing Resources, Inc. 
460 Oakmead Parkway 
Sunnyvale, CA 94086 
408-774-6100 



Detailed RP R Contort Information 

rZ^t° nal tCChnkal in , formation regarding InterTrust Commerce Architecture™ and DVD- 
^ZRJ^tiZSSSSF' ^ VM Wie ' SVP * V: WTTlSSi F: 

^vn dit !° n ^ buSi , nCSS information regarding InterTrust Commerce Architecture and DVD-related 



© 1996 Electronic Publishing Resources, Inc. 

M-5928 



Electronic Publishing Resources, Inc., 460 Oakmead Parkwav Sunnwoi- 

94086, 408-774-6100 drKwav » Sunnyvale, CA 



This brief paper summarizes an important set of technologies for rnn„„ mt „/ . , 

management that, if implemented by the consumer JtexS^^fi™*** ™ d nghts 
for rightsholders over the next several vean ^Ste fhJ f ^ W , U1 P reserve vitaI options 

provMeakey^ridge^nS 

The solution presented m this paper is based on wemhVonduc^^ 
Resources and its principal scientists stretching back more than 10 yS^SSSSSm^t 
include technologies for secure electronic commerce coovrieht Drot S • u, S cffort 
for both the consumer and computer marketsT^eT^ 

nS^£? a VF™ ? C end 10 cnd P^ ^ of this a PP S were comvktSl 

InterTrust is a modular, tamper-resistant, software technology that Drovides nmt^rtinn fXr 
digital properties of all kinds, including film, music, image, muffiS 
conjunc uon with cost-effective tamper-resistant hardware the leveT of protecdon^s SL 
substantial. Encryption will be useful in protecting intellectual S«SSS £ 

practical, that only authorized devices and users can decrypt the protected content Cunem 

mXfblfS^ ^ can ntake^very cfSffiSS^SSy 

impossible, for someone to compromise the protected digital property However SShnH, 

oftw?^ !m' ^ ° f the devicc control ,ogic ■*» infonSdon sucl^ as ScrJptSn key^nd ' 
inftZSsn W % °" a , Smg,C Chip ' 0r inside a tam P er resistant enclosure The SSed 

oulZo bLSS v S^TT^ thC ^ In * 0mc devices ' thc infoS Se chip 
Z : chic "self hteSSf"Ji 0lher dCV u 65 ' the 301 of accessing information would destroy 

3K^?8B» hardwarc - EPR refcriTo 3 work 

propSrV $ s e u C cTl k ^!i ea J S ^ ° nC can c as . S0 P iate one or more sets of business rules with a digital 
havSngle firl RSJ nTf E ? SUng C0 ™ P rotection methods for V <*s already 

uSed convi^a Pnf ? 10 'T 1 COpymg 10 a si "g le generation, as well as tVpermit 
SSTofSSSSST* 1 ' g l? TC ics ' togclher with business ™ ,c * concerning^ 
Z DVD medirT? d S; Ca 1! ^.FJ 2 "? ^ ? 3 tam ^istant software "container" stored 

T,ese same rules, or 

or mmi^Sl^S^ 3lS ° st0K A F^ intent in unencrypted form. For example, movie 
unScrtp ted !kd TZ&tSS"™*- 3Udl ° S3m P les ' trai,ers ' 3X1(1 advertising can be stored 
Sy p S£ o a EJ? 3 f T a PP™P nate apphcauon or device. At the s*ame time, valuable 
g properties of all lands-film, v.deo. .mage, text, software, and multimedia-can be stored 
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SSr&mSff ReS0UrCCS ' InC> ' 4 §° akmead P -kwa y , Sunnyvale, CA 

^SSS^SS^ ^ aUth -° riZCd dCViCeS 211(1 aPPUCati0nS 30(1 0nly Under ri 8 h ^older- 

nv^J^ST? 8 ? idCa ^ m u ltiplC 13 0f L njles can 1x1 storcd in the same DigiBox on the 
DVD disk. The foterTrust software then applies the appropriate rules depending on whether the 
movie is played by a consumer appliance or computer. Some usage rules may apply when the 
property is played by a consumer device and different rules may apply when plaved bv a commits 
Tins capability can also be used to provide users, particularly computer users; with choices abouT 
the set of niles that will apply. For example, a rightsholder may offer people using compute* both 
a pay per use and a one time fee model by including two rule sets for computer users 

The choice of rules is completely up to the rightsholders. For example, film rightsholders mav 
wish to limit copying and also ensure that exceipts are not taken from their content regardless of 
the context m which the property is played. Alternatively, rightsholders of sound recordings mav 
wish to enable excerpts of no more than 20 seconds, and that these excerpts are not used to 
construct a new commercial work without permission. 

In a digital consumer appliance, these rules can be enforced, provided a few additions are made 
to the microprocessor (-5k gates), and provided some ROM or flash memory' is made available to 
hold the necessary software. We believe that these additions will not add appreciable cost to the 
device. Devices can also be produced without InterTrust capability and outfitted with a socket to 
receive these capabilities in a field upgrade. 

In addition each ROM (or flash memory) can contain a digital document or "certificate" that 
uniquely identifies that particular appliance. The rules for a consumer appliance can ensure that a 
newDiaiRif * Sent to , another di ?^ devi <* ?nly in encrypted form and only inside a 

-3? !!• X may dS0 Car ? W,th 11 new m,es a PP ro P ria te for a copy, rather than the 
original rules. The sending consumer appliance may also put the unique identifier of the receiving 
device in the same secure container. Consequently, the new rules will ensure that the copy will be 
playable only on the intended receiving device. ^ 

The new rules can ensure that no additional copies are created. If the InterTrust software on a 
consumer appliance detects that a digital property is about to be played on a device other than the 
one it was intended for, it will to refuse to play that copy (if desired). 

The same restrictions that apply to a consumer appliance can be enforced on an InterTrust- 
aware computer In the above example, the rules could specify not to play this film on anything but 
a consumer appliance, or enforce the same rules on a computer. Alternatively, these same powerful 
capabilities could be used to specify different usage rules and payment schemes that would apply 
when played on the computer, based on the rightsholder's business model. 

No backchannel is required for any of the models presented here, however, when 
backchannels are present— for example, in settop boxes with bi-directional communications or 
computers attached to networks— it is easy to independently deliver new rules for a given property 
I hese new rules may specify discounts, time-limited sales, advertising subsidies, new general 
prices and so on. As noted earlier, determination of these independently delivered rules is entirely 
up to rightsholders. 3 
The solution to universal copy protection and rights management advocated here provides the 
cost-effective copy protection that rightsholders desire now, while at the same time laying a 
oundation for flexibility in the unforeseeable future. From the beginning. EPR designed InterTrust 
nJ^K-r? n S ht J w,th ^e powerful control capabilities they desire together with enormous 
iiexipuity regarding the rules f or copy protection, content distribution, and pricing models. 

'Flash memory (programmable memory), rather than ROM, may rum out to be the better solution 
to Firmware : because of its flexibility. The basic rationale is that rights management (indeed, all 
unctions of the player) may change over time. The second rationale is that experience has shown 
mat firmware bugs can undermine adoption of otherwise great technology. The third is that 
I! ™.? 1 Za j 10n m t y ^ ui [ e different ri S hts management decision-making (e.g. Japan does not 
S3 8 . % ? " ghtS m the same wa y that the US does - Therefore, it may make sense to 
nnpiemen the rules governing copy in a different way. For example, the ""no copy" rule in the US 

may actually be implemented as "one copy with a watermark") 
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Report of the Policy Group 
June 21, 1996 



Over the. past weeks, the policy group has held 11 meetings. Attending have 
been representatives from: the BSA, in, RIAA, MPAA, CEMA and HRRC, 
and persons from member companies. 

Representatives of ITI/BSA, CEMA/HRRC and MPAA have each tabled 
exploratory discussion drafts based on, or utilizing the concepts of anti- 
circumvention in conjunction with the introduction of digital video 
technologies. In addition, all parties, including RIAA, have amplified and 
clarified their respective key policy considerations (not limited to the 
circumvention issue) to be weighed in making decisions about specific 
technical and legislative proposals. Finally, each of the parties reaffirmed its 
commitment to finding the necessary ways and means to be supportive of the 
introduction of DVD technologies to the marketplace. 

There is broad agreement within the policy group that assuring compliance 
with copy protection systems requires legislation There is further agreement 
that such legislation needs to be based on making it illicit to circumvent, 
and/ or fail to fully implement, certain kinds of copy-protection systems. The 
policy group also agreed that decisions on policy issues would have to fully 
take into account further information on available technological 
solutions. 

The IT industry has proposed a two pronged approach to the issue of 
circumvention: 1) Prior to initial distribution of a copyrighted work, the 
content may be protected by direct application of an effective copy protection 
system, or a combination of such systems. 2) An obligation not to interfere 
with all, or any part, of such protection system(s), so long as the protection 
system(s) is adequately specified through an industry-led voluntary standards 
setting process, and it is widely implemented in respect of works intended for 
a specified class of devices. 

Counsel for the motion picture industry has suggested for discussion an anti- 
circumvention model which would make it illegal to sell tools, or otherwise 
assist or engage in, circumvention of copy protection systems. To be protected 
under this model, such copy protection systems would have to be specified or 
described through a "qualified voluntary standard," a concept which requires 
definition, and the possibility exists that such standards may, in certain cases, 
have to be established through law or regulation. MPAA would have such 
standards and establishment apply to D-A and A-D, as well as D-D, copying, at 
final and intermediate stages, and to back to back and transmission contexts. 
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t«*T£ l t ^ e J consumer electronics industry has tabled for discussion a 
model that includes an anti-circumvention provision. This model defines 
circumvention" in the context of obligations on makers and distributoS of 
devices with respect to (1) copy control technology applied to signals also 
protected by encryption or scrambling, and (2) copy control tedinology 
existing or applied after decryption/descrambling or in the absence of 
encryption or scrambling. It would provide an antitrust exemption for 
private sector agreement on a system or systems to be officially adopted It 
would also include provisions for the points deemed essential by CEMA and 
agreed to by MPAA in the context of their draft legislative proposal 

While both MPAA and CEMA have been willing in good faith to discuss 
^S"S Ve f ° n " b i S Gd id t aS pr °P° Sals of sort hypothesized by 

SSSSdS^wM f wished , for approach set forth * ^ mutua V 

agreed draft legislative proposal to remain open for consideration, in whole 
ui in udrr. 

Each of the parties also clarified their positions on their key policy 
considerations. y v y 

The motion picture industry articulated two considerations: preventing or 
inhibiting copying in the various circumstances where such copying might 
occur; and, ensuring compliance. . ^ y 8 S 

?a^ A JfT me T d d ? ht l UCh considera «°ns: the need for technical systems 
o be sufficiently specific that manufacturers would not be inadvertently liable 
for failure to comply; preservation of consumers' rights regarding copymg 

s^fo^r nufaCt T rS ° f products covered b y the legislation of exposure to 
private Z? ^gement; ^lieving consumers of exposure to suit for 
pnva e, non-commercial copying; ensuring technological compatibility 
ensuring the availability of technology needed to comply with^d/or 

a7uZXZ^r eCt ^ n SyStGmS With ^ te ^ogy royalty obligations 
bein^l^ a COp y ri ? ht , owners ^ °' whose rights the technology is 
remldt? 7 ' ^ ^ f ° r P rofessi °nal devices! and, taUoring of 

conduct CEMA tl0nS ' "!f 1Uding aV ° idanCe ° f multiple acti °ns & the same 
rfnnl^u generally concerned as to the level of expense and burden 

omeTdeviceT S ° 1Uti ° n might imp ° Se ° n burner electronics or 

dWtS^ a§reeS W ^ MPAA contro1 over c °Pyfag ^ the digital to 
SSSSS^^^ * rou « h -te—e Llog loop when 
rJc£*2 1 I? , i G) mUSt be 3 central featu re of any solution^. For sound 

"un^n^votS" b?f ^ ' m application of c °Py -ntrols from 
wdl as win f ^P^^oded digital sources such as existing CD's, as 
well as from all forms of digital transmissions from a digital source. While 
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RIAA continues to have concerns about digital codvW of a ^i~ 
ana bg copying of digital sou.cs, RIAA ha? not 7^ e iZ Z "* 
contemplated legislation or technical solution sp P ecSy Zl wfth ,W 
issues (other than the intermediate analog loop referred to eartiert *?r> n 
cham). IWs could be achieved either by drafting a c?mp^nS"e an£ 
circumvention provision broad enough to requife device to resnon^o 
embedded copyright management information, or by mandat£/™rfSl,,r 
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Agenda for June 21 DVD Meeting 

1. Report by the engineering group 

2. Report by the policy group 

3. Discussion of issues not addressed by the reports 

4. Discussion of next steps 



